When the Industry Standard Doesn’t Fit Your Business

Jun 12, 2026

Reading Time: 4 minutes

Why We Built SiAuth: Overcoming Enterprise SSO Friction

Identity & Access Management • Cloud Architecture • Cyber Security

Strategic Summary: Relying on default enterprise standards can sometimes introduce massive operational friction. When Microsoft Azure SSO created months of client onboarding delays for our Meridian platform, Si Futures engineered SiAuth—a hardened, scoped authentication engine. CEO Geordie Hogarth explains how stepping away from conventional SSO reduced client setup times from months to minutes while meeting strict Cyber Essentials compliance controls.

There is a version of technology decision-making that goes roughly like this: identify the industry standard, implement it, and move on. It is efficient, defensible, and wrong about as often as it is right.
We encountered this exact dilemma with identity and access management (IAM). Our Meridian platform—the internal operating stack we have refined over the past two years—required a dedicated authentication layer. Microsoft Single Sign-On (SSO) via Entra ID was the obvious answer. It is what most enterprise environments run, it integrates seamlessly across external tooling, and we already run Microsoft 365 across our business. The path of least resistance was clear—and we chose not to take it.

When the Standard Creates the Problem

Meridian includes inSight, our network intelligence and operational monitoring platform. We had been running our internal team access on Azure SSO without issue. However, when we started onboarding external clients—giving them direct visibility into their connectivity metrics and network health—we hit a major administrative wall.

To let an enterprise client log into an application via Azure SSO, their IT security team must authorize that third-party application inside their own Entra tenant. This is a sound security protocol. In practice, however, it acts as a massive operational friction point involving security reviews, change control committees, and stakeholder sign-offs. We once waited three months for a single SSO federation request to clear a client’s internal approval queue.

That meant three months of artificial delay before a client could access a platform they were paying for and that was already fully built and ready for deployment.

Building What the Requirement Actually Needs

SiAuth is our proprietary identity management layer, built on a hardened, open-source authentication platform. It manages identity across all Meridian applications—including inSight, NOC Brain, SiSmic, SiDekick, SiNapse, and SiNario Studio—for both our internal engineers and our external clients.

From a functional standpoint, SiAuth delivers everything Azure SSO provides: single sign-on, role-based access control (RBAC), multi-factor authentication (MFA), and user lifecycle management. The crucial structural difference is that it operates inside a closed, scoped environment.

We define its exact access boundaries. There is zero risk of inadvertently granting a client’s login broader permissions inside a Microsoft tenant than intended, because the system authenticates directly against our application infrastructure rather than Microsoft’s global directories.

Onboarding a new client now takes minutes rather than months.

“To be clear: we did not write cryptographic protocols from scratch. Rolling your own cryptography creates critical vulnerabilities; standing up a proven, open-source platform inside a tightly scoped environment is the exact opposite.”

When Security Controls and Operational Practicality Align

Building a custom identity system forces an organization to think rigorously about access mechanics. What are the enforced password parameters? How is account recovery verified? What constitutes a legitimate access request? Who can grant elevated permissions, and how often are those credentials audited?

We already possessed years of documented policies developed for enterprise environments. Pulling those into a unified framework for SiAuth produced a documentation pack that directly satisfied a major portion of our Cyber Essentials identity and access management requirements.

The engineering discipline required to deploy the system naturally generated the verified evidence that compliance frameworks demand. While compliance was not our original motivation for building SiAuth, it illustrates an important principle: security controls and operational practicality are not naturally in conflict. Organizations that find compliance burdensome are usually those treating security and daily operations as separate problems.

The Strategic Question Before Every Implementation

Our core mission is matching technology to genuine business needs. Microsoft SSO did not match ours—it matched a general industry pattern that generated specific friction for our clients.

The question we ask before implementing any technology, whether for our internal platform or for our clients, is whether the solution actually fits the requirement, or whether we are forcing a default standard into a situation that requires a tailored architectural approach. Sometimes the standard is ideal; sometimes it creates unnecessary overhead.

Modern, AI-assisted engineering has fundamentally shifted this calculus. Building a dedicated authentication layer is no longer a multi-quarter project requiring a massive team. We developed SiAuth as part of a broader engineering sprint, tested it thoroughly, and deployed it across our operations in weeks.

Identity management is a foundational operational control. How your business governs access matters far more than which tech giant’s logo appears on the login screen.

Key Business Outcomes of the SiAuth Architecture

By tailoring our identity layer to exact operational requirements, Si Futures achieved three key outcomes:

  • Rapid Client Onboarding: Reduced tenant federation wait times from 90+ days to under 5 minutes.
  • Strict Privilege Isolation: Prevented cross-tenant permission sprawl across client Microsoft 365 environments.
  • Audit-Ready Compliance: Automatically generated the evidence matrix required for Cyber Essentials IAM certification.
If the way your enterprise accesses its core tools creates friction rather than velocity, it is time to re-evaluate whether your security controls are truly working for your business.

Is Enterprise Tooling Slowing Down Your Operations?

Stop forcing off-the-shelf software standards into workflows that demand agility. Contact our cloud engineering group today to explore tailored identity, infrastructure, and managed cybersecurity solutions built around your exact business needs.

TALK TO OUR ENGINEERING TEAM

author avatar
Geordie Hogarth

Let’s connect